New Mac spyware found in the Oslo Freedom Forum

F-secure is reporting on new malware found for OS X, which appears to be a backdoor application that so far is known to take screenshots of the user’s computer and then attempt to upload them to remote servers. The malware is being called OSX/KitM.A.

It’s a small application called macs.app and was found on the Mac of an African activist who was a member of of the Oslo Freedom Forum. When installed, the application is appended to the current Mac user’s log-in items so it runs whenever the affected user account is logged in. It then takes regular screenshots that it places in a visible folder in the user’s home directory called MacApp. It then tries to upload them to the URLs “securitytable.org” and “docsforum.info,” which either are not working or are issuing “public access forbidden” error messages.

This bit of malware is somewhat unique in that it is signed with what appears to be a valid Apple Developer ID associated with the name Rajender Kumar. Though not an uncommon name, this may be a reference to the late Bollywood actor of a similar name. Regardless, the use of the ID appears to be an attempt to bypass Apple’s Gatekeeper execution prevention technology. (Read More)